CVE-2026-49190
Last modified
CVE-2026-49190 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Acer | Connect M6e 5g Firmware | <= m6e_ai_1.00.000019 |
References
- https://community.acer.com/en/kb/articles/19707Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-49190?
How severe is CVE-2026-49190?
How do I fix CVE-2026-49190?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49185The FieldX MDM adb messaging topic passes unverified payload…9.8
- CVE-2026-49186The local MQTT broker does not enforce topic-level Access Co…9.8
- CVE-2026-49187The hard-coded APK resource files never expire, and the shar…7.5
- CVE-2026-49188The ai_cmd utility executes with full root permissions. It p…9.8
- CVE-2026-49189Unchecked public access permissions on a core Broadcast Rece…7.8
- CVE-2026-4919IBM Guardium Data Protection 12.1 is vulnerable to cross-sit…4.8
- CVE-2026-49191The production build of the M3WebServer hard-codes its backe…9.8
- CVE-2026-49192The summary service endpoint suffers from an IDOR vulnerabil…5.4
- CVE-2026-49193Overly permissive configuration settings on cloud storage co…7.5
- CVE-2026-49194The debugging routine SCREEN_CLICK(5053) enables a connectio…8.8
- CVE-2026-49195Unauthenticated Debug Service. The /sbin/mtk_dut binary is e…8.8
- CVE-2026-49196The Wi-Fi device blocking feature fails to sanitize MAC addr…7.2
Are you affected by CVE-2026-49190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
